Checklist
AI Compliance & Governance Checklist
A structural self-check, not a certification. These are the questions we see skipped most often when an AI or automation system ships fast — data mapping, retention, residency, access control, human review, and what your model provider actually does with your data.
Data mapping
- □Can you name every system this data passes through, from entry to storage to any AI model call?
- □Do you know which fields are personal, sensitive, or regulated versus which are not?
- □Is there a diagram or document of this, or does it only exist in someone's head?
Retention and deletion
- □How long is data kept at each stage — including logs, model provider caches, and backups?
- □If someone asks you to delete their data, can you actually find and remove all of it?
- □Are retention periods a deliberate decision, or just whatever the default happened to be?
Data residency
- □Do you know which country/region your data (and any AI provider's processing of it) physically resides in?
- □Does that matter for your specific regulatory environment, and has anyone actually checked?
Access control
- □Who — people and systems — can actually see this data today, and is that list current?
- □Is there an audit log of who accessed what, or would you be guessing if asked?
- □Are AI model API keys and credentials scoped narrowly, or shared broadly for convenience?
Human-in-the-loop
- □For any AI-driven decision with real consequences, is there an explicit human review step?
- □Is there a way for someone affected by an AI decision to contest it or reach a person?
- □Is escalation a designed path, or does it only happen if someone happens to notice a problem?
Vendor and model-provider questions
- □Does your AI model provider train on your data by default, and have you actually checked the setting rather than assumed?
- □What does your provider's data processing agreement actually say about retention and subprocessors?
- □If you switched providers tomorrow, could you get your data out cleanly?
Documentation and auditability
- □Could you produce a written answer to 'how does this system handle our data' if a customer, auditor, or regulator asked tomorrow?
- □Is that documentation current, or does it describe an earlier version of the system?
This checklist exists because of a real, named pattern we see repeatedly — The Compliance Blind Spot. If any section above raised more questions than answers, that's the signal an AI Strategy & Audit is worth doing before (or alongside) a build.
Specific frameworks — what each actually requires
FAQs
Is this a legal compliance certification (SOC 2, ISO 27001, GDPR, etc.)?
No — this is a structural self-check for the questions that get skipped when a system ships fast, not a substitute for a qualified compliance audit or legal review. If you need certification-level assurance, that's a different, formal process with its own specialists — see our Compliance Frameworks reference for what each specific framework actually requires.
We're a small team — does this actually apply to us?
The questions scale down fine. A two-person team building an internal tool still benefits from knowing where data goes and whether an AI provider trains on it by default — it's just a shorter answer, not a skipped one.
What's the most commonly skipped item on this list?
Checking the AI model provider's actual data-training default, rather than assuming it doesn't train on your data. Most providers publish this clearly, but almost nobody reads it before integrating — see our Compliance Blind Spot failure pattern for how this plays out.
Have a project in mind?
Tell us what you're trying to automate or build — we'll reply with next steps, not a sales pitch.